New Method of Attack Abuses PowerPoint Slide Show
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
A new method of exploit has been discovered using a PowerPoint slideshow. The exploit arrives as an email attachment on an email claiming to be an Internet Service Provider as part of a spear-phishing campaign. When opened it shows the text “CVE-2017-8570” which is a different Microsoft Office vulnerability. CVE-2017-0199 is then exploited using a moniker script downloading a second-stage binary from a remote command and control server. This binary file finally downloads a Remote Access Trojan (RAT) and executes it.
Most ways of detecting CVE-2017-0199 focus on the RTF method of attack so the new vector, PPSX files, allows attackers to evade antivirus detection.
Remediation advice
Mitigation:Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 11:36 am